⤷ Title: CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:32:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #plugin #rce #Remote Code Execution #site takeover #Vulnerability #Wordfence #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:32:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Deletion #CVE_2025_6463 #cybersecurity #Forminator #plugin #rce #Remote Code Execution #site takeover #Vulnerability #Wordfence #wordpress
Daily CyberSecurity
CVE-2025-6463: Unauthenticated Arbitrary File Deletion in Forminator Plugin Exposes Over 600,000 WordPress Sites to Remote Takeover
A critical flaw (CVE-2025-6463, CVSS 8.8) in Forminator WordPress plugin allows unauthenticated arbitrary file deletion, leading to site takeover.
⤷ Title: Chinese Student Jailed for Smishing: Operated Covert “SMS Blaster” in Car for Mass Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:20:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Data Theft #DCPCU #Fraud #mobile security #phishing #Rogue Cell Tower #smishing #SMS Blaster #UK Police
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:20:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Data Theft #DCPCU #Fraud #mobile security #phishing #Rogue Cell Tower #smishing #SMS Blaster #UK Police
Daily CyberSecurity
Chinese Student Jailed for Smishing: Operated Covert "SMS Blaster" in Car for Mass Phishing
A Chinese student was jailed in London for running a smishing campaign with an "SMS Blaster" hidden in his car, spoofing texts to steal data.
⤷ Title: ANSSI Exposes “Houken”: China-Linked Threat Actor Exploiting Ivanti CSA Zero-Days & Deploying Linux Rootkits
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:08:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #ANSSI #APT #china #Cyberespionage #cybersecurity #Houken #initial access broker #Ivanti CSA #Linux Rootkit #MSS #UNC5174 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:08:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #ANSSI #APT #china #Cyberespionage #cybersecurity #Houken #initial access broker #Ivanti CSA #Linux Rootkit #MSS #UNC5174 #zero_day
Daily CyberSecurity
ANSSI Exposes "Houken": China-Linked Threat Actor Exploiting Ivanti CSA Zero-Days & Deploying Linux Rootkits
ANSSI exposes "Houken," a China-linked APT exploiting Ivanti CSA zero-days (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) and deploying Linux rootkits for cyber-espionage against strategic sectors.
⤷ Title: OFAC Sanctions Russian “Bulletproof Host” Aeza Group: Linked to Ransomware, Infostealers & Darknet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:57:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aeza Group #BPH #bulletproof hosting #Cybercrime #cybersecurity #Darknet #Infostealer #OFAC #ransomware #russia #sanctions #Treasury Department
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:57:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aeza Group #BPH #bulletproof hosting #Cybercrime #cybersecurity #Darknet #Infostealer #OFAC #ransomware #russia #sanctions #Treasury Department
Daily CyberSecurity
OFAC Sanctions Russian "Bulletproof Host" Aeza Group: Linked to Ransomware, Infostealers & Darknet
OFAC sanctioned Russia's Aeza Group, a bulletproof hosting provider, and its executives for enabling ransomware, infostealers (Meduza, Lumma), and darknet drug trafficking operations globally.
⤷ Title: DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:46:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:46:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #DOJ #DPRK #fbi #money laundering #national security #North Korea #Remote IT Jobs #Sanctions Evasion #scam #Stolen Identities
Daily CyberSecurity
DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
The DOJ dismantled a North Korean scheme exploiting remote IT jobs at 100+ U.S. firms, using stolen identities and laundering millions to fund DPRK weapons programs.
⤷ Title: Write-up Hack the system Sattracker
════════════════════════
𐀪 Author: D4LTON
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:06:03 GMT
════════════════════════
⌗ Tags: #ctf #web #bug_bounty #hack_the_system #htb
════════════════════════
𐀪 Author: D4LTON
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:06:03 GMT
════════════════════════
⌗ Tags: #ctf #web #bug_bounty #hack_the_system #htb
Medium
Write-up Hack the system Sattracker
You hack the system not because it’s easy… but because it dares you.
⤷ Title: gf: Your Essential Ally for Vulnerability Recognition and Detection in Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:02:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #infosec #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:02:56 GMT
════════════════════════
⌗ Tags: #ethical_hacking #penetration_testing #infosec #cybersecurity #bug_bounty
Medium
gf: Your Essential Ally for Vulnerability Recognition and Detection in Bug Bounty
Discover gf and its patterns to filter sensitive data, detect vulnerabilities, and optimize your reconnaissance in pentesting and bug…
⤷ Title: Is It Safe to Use Public Charging Stations? Here’s What You Need to Know
════════════════════════
𐀪 Author: Abijita Foundation
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:29:47 GMT
════════════════════════
⌗ Tags: #hacking #juice_jacking #privacy
════════════════════════
𐀪 Author: Abijita Foundation
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:29:47 GMT
════════════════════════
⌗ Tags: #hacking #juice_jacking #privacy
Medium
Is It Safe to Use Public Charging Stations? Here’s What You Need to Know
I was scrolling Facebook and noticed a meme that read, “The only warning I take seriously is my phone’s low battery warning.” It sounds…
⤷ Title: The Heart of Modern Communication: A Deep Dive into the TCP/IP Architecture
════════════════════════
𐀪 Author: Muhammet Alperen Şıvgın
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:42:09 GMT
════════════════════════
⌗ Tags: #technology #computer_networking #internet #cybersecurity #network
════════════════════════
𐀪 Author: Muhammet Alperen Şıvgın
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:42:09 GMT
════════════════════════
⌗ Tags: #technology #computer_networking #internet #cybersecurity #network
Medium
The Heart of Modern Communication: A Deep Dive into the TCP/IP Architecture
Discover how the internet really works — from HTTP requests to IP packets — with a beginner-friendly guide to the TCP/IP model.
⤷ Title: Understanding IPv4 Address Classes and Subnetting
════════════════════════
𐀪 Author: Samira Fallah
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:29:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #subnetting #ip #network_security
════════════════════════
𐀪 Author: Samira Fallah
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:29:32 GMT
════════════════════════
⌗ Tags: #cybersecurity #subnetting #ip #network_security
Medium
Understanding IPv4 Address Classes and Subnetting
When IPv4 was initially designed, no one anticipated how rapidly and extensively the internet would grow. Initially, IPv4 addresses were…
⤷ Title: Why Zero Trust is Not a product but a strategy you can’t ignore in 2025
════════════════════════
𐀪 Author: Badaolaitan
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:26:15 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #phishing #cybersecurity #cyberattack #zero_trust
════════════════════════
𐀪 Author: Badaolaitan
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:26:15 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #phishing #cybersecurity #cyberattack #zero_trust
Medium
Why Zero Trust is Not a product but a strategy you can’t ignore in 2025
“We recently purchased a Zero Trust solution.” A statement like that makes even the most seasoned security experts cringe. Zero Trust is a…
⤷ Title: Fraud Scheme: How Fake LLCs Are Used to Commit Loan Fraud
════════════════════════
𐀪 Author: Internet Exposed
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:18:17 GMT
════════════════════════
⌗ Tags: #fraud #business_fraud #cybersecurity
════════════════════════
𐀪 Author: Internet Exposed
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:18:17 GMT
════════════════════════
⌗ Tags: #fraud #business_fraud #cybersecurity
Medium
🚨 Fraud Scheme: How Fake LLCs Are Used to Commit Loan Fraud
This scheme relies on exploiting loopholes in business registration, identity verification, and lending systems, especially among online…
⤷ Title: From Survival to Code: My Journey as Zwanski
════════════════════════
𐀪 Author: zwanski tech
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:12:11 GMT
════════════════════════
⌗ Tags: #technology #personal_development #refugee_experience #about_me #cybersecurity
════════════════════════
𐀪 Author: zwanski tech
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:12:11 GMT
════════════════════════
⌗ Tags: #technology #personal_development #refugee_experience #about_me #cybersecurity
Medium
From Survival to Code: My Journey as Zwanski
⤷ Title: Setting Up the Environment
════════════════════════
𐀪 Author: 3Graces CC
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:37:01 GMT
════════════════════════
⌗ Tags: #virtualization #soft_skills #technology #blue_team #cybersecurity
════════════════════════
𐀪 Author: 3Graces CC
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 01:37:01 GMT
════════════════════════
⌗ Tags: #virtualization #soft_skills #technology #blue_team #cybersecurity
Medium
Setting Up the Environment
Before diving into the technical setup, I want to emphasize something easily overlooked in projects like these: the importance of soft…
⤷ Title: Billing TryHackMe Walkthrough
════════════════════════
𐀪 Author: Rich
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:07:41 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #linux_security #tryhackme_walkthrough #tryhackme #apache_security
════════════════════════
𐀪 Author: Rich
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:07:41 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #linux_security #tryhackme_walkthrough #tryhackme #apache_security
Medium
Billing TryHackMe Walkthrough
TL;DR Walkthrough of the TryHackMe Billing room.
⤷ Title: Bypassing GraphQL Brute Force Protections
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:53:51 GMT
════════════════════════
⌗ Tags: #bug_bounty #graphql_rate_limit_bypass #brute_force_graphql_api #graphql_brute_force #bug_bounty_tips
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 02:53:51 GMT
════════════════════════
⌗ Tags: #bug_bounty #graphql_rate_limit_bypass #brute_force_graphql_api #graphql_brute_force #bug_bounty_tips
Medium
Bypassing GraphQL Brute Force Protections
A deep dive into exploiting weak rate limiting in GraphQL APIs and how attackers bypass protection mechanisms.
⤷ Title: Stealthy WordPress Malware Uncovered: Multi-Stage RAT Injects via Header.php, Hides Traces
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 04:05:02 +0000
════════════════════════
⌗ Tags: #Malware #Client32.exe #cybersecurity #Header.php #malware #Multi_stage Malware #RAT #Remote Access Trojan #Sucuri #web security #Web Shell #WordPress
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 04:05:02 +0000
════════════════════════
⌗ Tags: #Malware #Client32.exe #cybersecurity #Header.php #malware #Multi_stage Malware #RAT #Remote Access Trojan #Sucuri #web security #Web Shell #WordPress
Penetration Testing Tools
Stealthy WordPress Malware Uncovered: Multi-Stage RAT Injects via Header.php, Hides Traces
Sucuri uncovers a complex multi-stage malware campaign infecting WordPress sites via header.php to deliver a hidden RAT (client32.exe) and evade detection.
⤷ Title: DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:54:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybercrime #DOJ #DPRK #FBI #Money Laundering #National Security #North Korea #Remote IT Jobs #Sanctions Evasion #Scam #Stolen Identities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:54:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybercrime #DOJ #DPRK #FBI #Money Laundering #National Security #North Korea #Remote IT Jobs #Sanctions Evasion #Scam #Stolen Identities
Penetration Testing Tools
DOJ Dismantles North Korean IT Job Scam: Stolen Identities & Laundering Funded DPRK Weapons
The DOJ dismantled a North Korean scheme exploiting remote IT jobs at 100+ U.S. firms, using stolen identities and laundering millions to fund DPRK weapons programs.
⤷ Title: International Criminal Court Hit by “Sophisticated and Targeted” Cyberattack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:51:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyberattack #cybersecurity #data breach #Espionage #Geopolitics #ICC #International Criminal Court #The Hague #War Crimes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:51:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #cyberattack #cybersecurity #data breach #Espionage #Geopolitics #ICC #International Criminal Court #The Hague #War Crimes
Penetration Testing Tools
International Criminal Court Hit by "Sophisticated and Targeted" Cyberattack
The International Criminal Court (ICC) in The Hague was hit by a sophisticated, targeted cyberattack last week, the second in two years, prompting an investigation into the breach.
⤷ Title: Microsoft Authenticator Ends Password Support: Full Phase-Out by August 1, 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:41:23 +0000
════════════════════════
⌗ Tags: #Microsoft #Authenticator App #Autofill #cybersecurity #Edge Browser #MFA #Passwordless #passwords #Tech News #two_factor authentication
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:41:23 +0000
════════════════════════
⌗ Tags: #Microsoft #Authenticator App #Autofill #cybersecurity #Edge Browser #MFA #Passwordless #passwords #Tech News #two_factor authentication
Penetration Testing Tools
Microsoft Authenticator Ends Password Support: Full Phase-Out by August 1, 2025
Microsoft will end password support in its Authenticator app by August 1, 2025, phasing out autofill in July. Users must migrate passwords to Edge or other managers.
⤷ Title: Urgent Chrome Zero-Day Alert: CVE-2025-6554 (Type Confusion) Actively Exploited in the Wild
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:39:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #chrome #CVE_2025_6554 #cybersecurity #Exploited in Wild #Google Chrome #JavaScript Engine #RCE #remote code execution #Type Confusion #V8 #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 02 Jul 2025 03:39:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #chrome #CVE_2025_6554 #cybersecurity #Exploited in Wild #Google Chrome #JavaScript Engine #RCE #remote code execution #Type Confusion #V8 #vulnerability #zero_day
Penetration Testing Tools
Urgent Chrome Zero-Day Alert: CVE-2025-6554 (Type Confusion) Actively Exploited in the Wild
Google has urgently patched a high-severity zero-day (CVE-2025-6554) in Chrome's V8 JavaScript engine. This type confusion flaw is actively exploited in the wild, risking RCE.